Slide 27 of 28
Part 4 — PreventionSlide 27
Slide 27 · Quiz
Test what you know
Five questions. No memorization required — just understanding.
QUESTION 01 OF 05
A customer service agent issues an unauthorized refund using its legitimate refund API tool. The authorization check passed and the tool worked correctly. What is the key reason this is a security failure?
QUESTION 02 OF 05
An agent has both a CRM query tool and an email send tool. An attacker crafts a message that causes the agent to query all customer records and email them to an external address. Each individual tool call was authorized. What type of ASI02 attack is this?
QUESTION 03 OF 05
In the Amazon Q Developer DNS exfiltration incident, how did the attacker exfiltrate secrets?
QUESTION 04 OF 05
You have an agent with a ping tool in its auto-approved toolkit. Why is this still a security risk even if ping seems harmless?
QUESTION 05 OF 05
If you can only implement two of the seven ASI02 mitigations, which two provide the highest coverage across the widest range of attack scenarios?
← Back Done → See what you learned